Engine on Render
Render runs the engine image as a web service. The free instance type works for a demo or a staging engine.
Before you start
Section titled “Before you start”- A Render account.
- A Postgres database. On Supabase or Neon, use the connection string each page recommends.
Deploy
Section titled “Deploy”- Create a web service that deploys an existing image, and enter
ghcr.io/lyeve-labs/lyeve-core:latest. Pin a release tag in production. See Docker images. - Choose the API with
PORT. Render sends traffic to the portPORTnames, and the image's built-in health check probes that port too.PORT=3001publishes the Admin API, which you need to create the first administrator and define content types.PORT=3002publishes the Content API for your sites and apps.
Do not run a second Render service from the image for the other port. Each service creates its own signing key, so a token issued by one is refused by the other.
Secrets
Section titled “Secrets”Set these in the service's environment:
DATABASE_URL=postgres://<user>:<password>@<host>:5432/<dbname>?sslmode=requireDATABASE_MAX_CONNECTIONS=5JWT_SECRET=<openssl rand -hex 32>ENCRYPTION_KEY=<a different openssl rand -hex 32>LYEVE_AUDIT_HMAC_KEY=<a third openssl rand -hex 32>RATE_LIMIT_RPS=100SECURE_COOKIE=trueCORS_ORIGINS=https://your-app.example.comPORT=3001Production refuses to start without these values. Configuration lists every check.
Database
Section titled “Database”Free Postgres plans have tight connection limits, and an engine that restarts after every
spin-down reconnects each time, so keep DATABASE_MAX_CONNECTIONS small.
Supported databases lists the URL forms.
Health checks
Section titled “Health checks”Set the service's health check path to /readyz. Both listeners serve /healthz, /readyz
and /startup without authentication. Do not use /api/admin/health or /api/v1/health:
they need authentication, so a check gets 401 and marks a healthy service down.
Health endpoints says what each one checks.
Verify
Section titled “Verify”With PORT=3001:
curl https://your-service.onrender.com/api/admin/setupA new install answers {"setup_required":true,"token_source":"log"}. The setup token is the
one-time setup_token in the service's log, or LYEVE_SETUP_TOKEN when you set it. The
quickstart continues from step 2.
With PORT=3002:
curl https://your-service.onrender.com/.well-known/jwks.jsonThe first request after idle time is slow, and the next ones are fast until the service spins down again.
- Free-tier stack: the $0 recipe and its limits.
- Production checklist: what to confirm before real traffic.